Description
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4785
https://github.com/lifion/lifion-verify-deps/commit/be1133d5b78e3caa0004fa60207013dca4e1bf38
Related Vulnerabilities
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-solrj
CVE-2015-9241 Vulnerability in npm package hapi
CVE-2021-29620 Vulnerability in maven package com.epam.reportportal:service-api
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2016-10703 Vulnerability in maven package org.webjars.npm:ecstatic